Host computer intrude detecting method decomposed based on inherent subsequence mode
A technology of intrusion detection and pattern decomposition, applied in computer security devices, instruments, electrical digital data processing, etc., can solve the problems that intrusion detection cannot be universally applied, the process of calling NativeAPI is complicated, and it is difficult to apply it in practice
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment Construction
[0078] The present invention is further described below in conjunction with embodiment.
[0079] 1. Windows Native API
[0080] There are two modes in Windows, user mode and kernel mode. User applications run in user mode, while system programs run in kernel mode. The important difference between the two modes is that they have different priorities for processing files, calling memory, and using the CPU. Kernel mode has a higher priority than user mode. Even if a serious error occurs in the user application program, it will not cause too much impact on the entire system, ensuring the normal operation of the operating system.
[0081] API is the interface function of Windows operating system to provide users with system services in the dynamic link library, running in user mode or kernel mode. The API running in the kernel mode is NativeAPI, which is the interface function of the kernel-level system service in the dynamic link library. The Native API is very different from ...
PUM
Abstract
Description
Claims
Application Information
- R&D Engineer
- R&D Manager
- IP Professional
- Industry Leading Data Capabilities
- Powerful AI technology
- Patent DNA Extraction
Browse by: Latest US Patents, China's latest patents, Technical Efficacy Thesaurus, Application Domain, Technology Topic, Popular Technical Reports.
© 2024 PatSnap. All rights reserved.Legal|Privacy policy|Modern Slavery Act Transparency Statement|Sitemap|About US| Contact US: help@patsnap.com